1. Overview
This Privacy Policy describes how Yomi ("we", "us") — a product of Grit Digital Hub — collects, uses, stores, and protects information when you access or use our personalized reading-path and knowledge-matrix service at Yomi — Grit Digital Hub.
By creating an account or continuing to use Yomi, you confirm that you have read and understood this Policy. If you do not agree, please stop using the service.
2. Information we collect
Depending on the features you use, we collect the following types of data:
- Account data: when you sign in via Google OAuth or email OTP, we receive and store your display name, email address, profile photo (if provided by the auth provider), and an internal account identifier.
- Profile data you provide: date of birth, personal indicators, and other information you enter in Concierge flows or profile updates — used to analyze personal energy and life trajectory.
- Service usage data: saved knowledge maps, book recommendations, Premium interactions (if applicable), and minimal technical logs (access time, device/browser type) for operations and security.
- Payment metadata: when you pay for Premium, we may receive transaction IDs, payment status, and reference email from payment gateways — not full card numbers or bank account details.
3. Personal energy profile data
Yomi processes personal energy profile data (e.g. date of birth, indicators you enter) to build knowledge matrices and reading paths aligned with your development stage.
This data is stored on secure cloud infrastructure (Supabase) and accessed by our systems only when you request analysis or review saved maps. We do not sell your personal energy profile to third parties.
4. How we use data
We use data to:
- Personalize reading paths, knowledge matrices, and book recommendations aligned with your life trajectory.
- Operate accounts, authenticate sign-in, sync your Life Library, and deliver Premium features (where applicable).
- Improve recommendation algorithms, analysis quality, and user experience — often in aggregated or anonymized form where feasible.
- Detect abuse, fraud, scraping, or harmful behavior toward the system.
5. Data sharing and AI processing
To generate book suggestions and knowledge-matrix analysis, Yomi may send anonymized data — without direct personally identifiable information (PII) such as name, email, or account identifiers — to third-party AI model providers, currently including OpenAI and/or Google Gemini API.
We commit not to share PII (legal name, email, avatar, directly linkable account IDs) with AI APIs. Payloads contain only analysis context needed for the request (e.g. energy indicators decoupled from identity, development stage, book themes) per our technical design.
AI providers process data under their own terms and policies. We select partners with appropriate security commitments and minimize data sent to what is strictly necessary per analysis request.
Beyond AI, we use Supabase (auth, database), Resend (OTP email), payment gateways (Stripe, PayPal, bank transfer), and cloud infrastructure — each receiving data only within the scope of providing services to Yomi.
6. Payments
Premium payments are processed through secure intermediary gateways (e.g. Stripe, PayPal, or bank transfer per in-app instructions).
Yomi does not store credit card numbers, CVV codes, or full bank account details in our database. Sensitive payment information is handled directly by payment gateways under PCI-DSS or equivalent standards.
8. Data security
We apply reasonable technical and organizational measures: transport encryption (TLS), access controls (RBAC/RLS on Supabase), API permission limits, and anomaly monitoring.
No system is perfectly secure. If we discover a security incident affecting personal data, we will notify as required by applicable law and remediate within a reasonable time.
9. Data retention
We retain account and energy profile data while you maintain an account or as required by law or contract. Technical logs may be kept for shorter periods for security and operations.
When you request account deletion, we delete or anonymize related personal data within a reasonable time, except data we must retain for legal obligations or short backup cycles.
10. Your rights
Depending on applicable law in your country or region, you may have the right to:
- Access and receive a copy of personal data we hold about you.
- Correct or update inaccurate profile information in the app or via support request.
- Request deletion of your account and all associated data at any time — we process within a reasonable time after identity verification.
- Withdraw consent or object to certain processing where law permits.
To exercise these rights, contact us using the email in the Contact section. We may require identity verification before processing.
11. Children and policy changes
Yomi is not directed at users under 13 (or a higher minimum age under local law). We do not knowingly collect children's data. If you believe a child has provided data, contact us for deletion.
We may update this Policy. Material changes will be posted on this page with a new "Last updated" date. Continued use after the effective date means acceptance of the new version, unless law requires otherwise.
12. Contact
For privacy questions, profile corrections, or personal data deletion requests, contact the Yomi operations team directly using the form below.